← Back to all threat actors

AppleJeus

Also known as Gleaming Pisces, Citrine Sleet, UNC1720, UNC4736
Tracked as G1049

AppleJeus is a North Korean state-sponsored threat group attributed to the Reconnaissance General Bureau. Associated with the broader Lazarus Group umbrella of actors, AppleJeus has been active since at least 2018 and is closely aligned in resources with TEMP.hermit, another DPRK-affiliated group under the same umbrella. The group’s primary mission is to generate and launder revenue to provide financial support to the government. AppleJeus primarily targets the cryptocurrency industry and is most notably responsible for the 3CX Supply Chain Attack. The group traditionally deploys malicious cryptocurrency software in combination with Phishing. From these compromised environments, it selectively deploys additional backdoors to enable extended operations against high-value financial targets.

How we source and review actor profiles
Motivation
nation-state
Status
Active

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

Cataloged
IdentityTracking identifier: G1049

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Gleaming Pisces

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Citrine Sleet

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: UNC1720

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: UNC4736

Reviewed identity mapping approved on this date.

Last observed
Campaign3CX Supply Chain Attack

The 3CX Supply Chain Attack was the first publicly reported case of one supply chain compromise triggering another, leading to a cascading, two-stage intrusion. The initial supply chain attack began when a 3CX employee downloaded and e…

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

AppleJeusCanonical Name
Citrine SleetAlias
Gleaming PiscesAlias
UNC1720Alias
UNC4736Alias
G1049Tracking Id

Loading CVEs, techniques, indicators, malware, victims, and activity...